US2024388996A1PendingUtilityA1

Traffic-based tunnel endpoint assignment for local area networks

Assignee: CISCO TECH INCPriority: May 17, 2023Filed: May 17, 2023Published: Nov 21, 2024
Est. expiryMay 17, 2043(~16.8 yrs left)· nominal 20-yr term from priority
H04W 40/246
59
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A network function orchestrator (NFO) of a local area network (LAN) controller can configure multiple different tunnel endpoints in the LAN based on network traffic observed within the LAN. The NFO can monitor network traffic communicated from client devices and through access points in the LAN. The network traffic can be associated with multiple different destinations. The NFO can determine, based on the network traffic and using network topology data, network devices to serve as tunnel endpoints within the LAN. Different tunnel endpoints can be configured for use in connection with different traffic destinations. The NFO can communicate with the network devices and the access points to configure the LAN to use the different tunnel endpoints.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method performed at least partly by a network function orchestrator, comprising:
 monitoring network traffic communicated from client devices and through access points in a local area network, wherein the network traffic comprises multiple different destinations;   determining, based at least in part on the monitoring, the multiple different destinations;   receiving network topology data indicating a topology of network devices in the local area network;   determining, using the network topology data, a first network device within the local area network to serve as a first tunnel endpoint and a second network device within the local area network to serve as a second tunnel endpoint;   communicating with the first network device to configure the first network device to act as the first tunnel endpoint, wherein the first tunnel endpoint is adapted to:
 receive first network traffic via first tunnels from the access points, wherein the first network traffic is destined to a first destination of the multiple different destinations; and 
 forward the first network traffic to the first destination; 
   communicating with the second network device to configure the second network device to act as the second tunnel endpoint, wherein the second tunnel endpoint is adapted to:
 receive second traffic via second tunnels from the access points, wherein the second network traffic is destined to a second destination of the multiple different destinations; and 
 forward the second network traffic to the second destination; 
   providing the first network device with first policies to apply to the first network traffic received via the first tunnels; and   providing the second network device with second policies to apply to the second network traffic received via the second tunnels.   
     
     
         2 . The method of  claim 1 , wherein the determining, using the network topology data, the first network device within the local area network to serve as the first tunnel endpoint and the second network device within the local area network to serve as the second tunnel endpoint is based at least in part on first and second network distances, respectively, wherein the first network distance comprises a network distance between the first network device and the first destination, and wherein the second network distance comprises a network distance between the second network device and the second destination. 
     
     
         3 . The method of  claim 1 , further comprising:
 determining the first policies to apply to the first network traffic, wherein the first policies comprise a first portion of network policies applicable to the network traffic, wherein the first portion of the network policies is applicable to the first destination; and   determining the second policies to apply to the second network traffic, wherein the second policies comprise a second portion of the network policies applicable to the network traffic, wherein the second portion of the network policies is applicable to the second destination.   
     
     
         4 . The method of  claim 1 , wherein the first tunnels and the second tunnels comprise control and provisioning of wireless access points (CAPWAP) tunnels. 
     
     
         5 . The method of  claim 1 , wherein the network function orchestrator is located at a cloud location that is outside the local area network. 
     
     
         6 . The method of  claim 1 , wherein the first destination is an authentication server, wherein the first network traffic comprises authentication traffic, and wherein the first tunnel endpoint is adapted to receive the authentication traffic and forward the authentication traffic to the authentication server. 
     
     
         7 . The method of  claim 1 , wherein the first destination is a dynamic host control protocol (DHCP) server, wherein the first network traffic comprises DHCP traffic, and wherein the first tunnel endpoint is adapted to receive the DHCP traffic and forward the DHCP traffic to the DHCP server. 
     
     
         8 . The method of  claim 1 , wherein the first destination is one of a public internet destination accessible via the public internet, a local destination within the local area network, or a private data center location within a private data center. 
     
     
         9 . A system comprising a network function orchestrator, the system comprising:
 one or more processors; and   one or more computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:   monitoring network traffic communicated from client devices and through access points in a local area network, wherein the network traffic comprises multiple different destinations;   determining, based at least in part on the monitoring, the multiple different destinations;   receiving network topology data indicating a topology of network devices in the local area network;   determining, using the network topology data, a first network device within the local area network to serve as a first tunnel endpoint and a second network device within the local area network to serve as a second tunnel endpoint;   communicating with the first network device to configure the first network device to act as the first tunnel endpoint, wherein the first tunnel endpoint is adapted to:
 receive first network traffic via first tunnels from the access points, wherein the first network traffic is destined to a first destination of the multiple different destinations; and 
 forward the first network traffic to the first destination; 
   communicating with the second network device to configure the second network device to act as the second tunnel endpoint, wherein the second tunnel endpoint is adapted to:
 receive second traffic via second tunnels from the access points, wherein the second network traffic is destined to a second destination of the multiple different destinations; and 
 forward the second network traffic to the second destination; 
   providing the first network device with first policies to apply to the first network traffic received via the first tunnels; and   providing the second network device with second policies to apply to the second network traffic received via the second tunnels.   
     
     
         10 . The system of  claim 9 , wherein the determining, using the network topology data, the first network device within the local area network to serve as the first tunnel endpoint and the second network device within the local area network to serve as the second tunnel endpoint is based at least in part on first and second network distances, respectively, wherein the first network distance comprises a network distance between the first network device and the first destination, and wherein the second network distance comprises a network distance between the second network device and the second destination. 
     
     
         11 . The system of  claim 9 , wherein the operations further comprise:
 determining the first policies to apply to the first network traffic, wherein the first policies comprise a first portion of network policies applicable to the network traffic, wherein the first portion of the network policies is applicable to the first destination; and   determining the second policies to apply to the second network traffic, wherein the second policies comprise a second portion of the network policies applicable to the network traffic, wherein the second portion of the network policies is applicable to the second destination.   
     
     
         12 . The system of  claim 9 , wherein the first tunnels and the second tunnels comprise control and provisioning of wireless access points (CAPWAP) tunnels. 
     
     
         13 . The system of  claim 9 , wherein the network function orchestrator is located at a cloud location that is outside the local area network. 
     
     
         14 . The system of  claim 9 , wherein the first destination is an authentication server, wherein the first network traffic comprises authentication traffic, and wherein the first tunnel endpoint is adapted to receive the authentication traffic and forward the authentication traffic to the authentication server. 
     
     
         15 . The system of  claim 9 , wherein the first destination is a dynamic host control protocol (DHCP) server, wherein the first network traffic comprises DHCP traffic, and wherein the first tunnel endpoint is adapted to receive the DHCP traffic and forward the DHCP traffic to the DHCP server. 
     
     
         16 . The system of  claim 9 , wherein the first destination is one of a public internet destination accessible via the public internet, a local destination within the local area network, or a private data center location within a private data center. 
     
     
         17 . A method comprising:
 receiving, by a first network device in a local area network, from a network function orchestrator for a local area network, first configuration data to configure the first network device to act as a first tunnel endpoint;   applying, by a first network device, the first configuration data to the first network device to enable the first network device to act as the first tunnel endpoint, wherein the first tunnel endpoint is adapted to:
 receive first network traffic via first tunnels from access points of the local area network, wherein the first network traffic is destined to a first destination of multiple different destinations; and 
 apply first policies to the first network traffic received via the first tunnels; and 
 forward the first network traffic to the first destination; 
   receiving, by a second network device in the local area network, from the network function orchestrator for the local area network, second configuration data to configure the second network device to act as a second tunnel endpoint;   applying, by a second network device, the second configuration data to the second network device to enable the second network device to act as the second tunnel endpoint, wherein the second tunnel endpoint is adapted to:
 receive second network traffic via second tunnels from the access points of the local area network, wherein the second network traffic is destined to a second destination of multiple different destinations; and 
 apply second policies to the second network traffic received via the second tunnels; and 
 forward the second network traffic to the second destination; 
   receiving, by the first network device, the first network traffic via the first tunnels from the access points of the local area network;   applying, by the first network device, the first policies to the first network traffic received via the first tunnels; and   forwarding, by the first network device, the first network traffic to the first destination;   receiving, by the second network device, the second network traffic via the second tunnels from the access points of the local area network;   applying, by the second network device, the second policies to the second network traffic received via the second tunnels; and   forwarding, by the second network device, the second network traffic to the second destination.   
     
     
         18 . The method of  claim 17 , wherein:
 the first network device is associated with a first network distance to the first destination and a second network distance to the second destination;   the second network device is associated with a third network distance to the first destination and a fourth network distance to the second destination;   the first network distance is shorter than the third network distance; and   the fourth network distance is shorter than the second network distance.   
     
     
         19 . The method of  claim 17 , wherein the network function orchestrator is located at a cloud location that is outside the local area network. 
     
     
         20 . The method of  claim 17 , wherein the first tunnels and the second tunnels comprise control and provisioning of wireless access points (CAPWAP) tunnels.

Join the waitlist — get patent alerts

Track US2024388996A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.